CVE-2025-66278: File Station 5
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66278?
CVE-2025-66278 is classified as a critical severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2025-66278?
To fix CVE-2025-66278, upgrade to Synology File Station 5 version 5.5.6.5190 or later, or QNAP File Station between versions 5.5.6.4691 and 5.5.6.5190 inclusive.
What does CVE-2025-66278 vulnerability exploit?
CVE-2025-66278 exploits a path traversal vulnerability that allows attackers with user accounts to access unexpected files or system data.
Who is affected by CVE-2025-66278?
Users of Synology File Station 5 versions up to 5.5.6.5190 and QNAP File Station versions between 5.5.6.4691 and 5.5.6.5190 are affected by CVE-2025-66278.
Is authentication required to exploit CVE-2025-66278?
Yes, exploitation of CVE-2025-66278 requires the attacker to have a valid user account for the affected systems.